Security Tools
128 best Security tools and apps, curated and ranked by community upvotes on ProductCool. Updated daily as new Security products launch.
The person on your next video call might not be real. With Halo you don't have to guess. Halo secures your Zoom, Teams, or Google Meet call live and flags synthetic faces the moment it detects one, entirely on your device. Deepfake video calls are already being used to scam people and businesses around the world, it's just that most people have no way to tell. From confirming who you're hiring to confirming who you're wiring money to, Halo catches it before it costs you.
The AI Agent Governance Toolkit provides a comprehensive framework for securing and managing autonomous AI agents in production. It solves critical challenges in agentic AI, including policy enforcement, identity management, sandboxed execution, and reliability, directly addressing the OWASP Agentic Top 10 security risks. It is designed for developers, platform engineers, and security teams building and deploying reliable, enterprise-ready AI agent systems.
Run curl qsa.sh for a one-command external security scan of your server's own public IP — naabu, nmap + vulners, and nuclei map your open ports, service versions, and known CVEs, streamed straight to your terminal in ~30 seconds. See exactly what the internet sees of your host: no account, nothing stored. Free scans run live; paid Pro (all 65,535 ports, async) and one-time Deep (the full nuclei firehose, emailed) dig deeper uncovering vulnerabilities below the surface.
Open-source AI CLI that answers security questions across cloud, code and runtime - GitHub, GitLab, AWS, GCP, Azure, K8s. Ask in plain language: "what's publicly exposed that shouldn't be?" or "can my CI escalate to cloud admin?". Read-only by construction: every call is resolved to its IAM actions and authorized against a read-only policy before credentials attach. It can't modify your infra even if asked. Unlike MCP tools, it writes JS in a sandboxed runtime - a script per turn, not one call.
HOL Guard is the firewall for AI agents. It sits between agents and your systems, blocking high-risk actions before they happen like deleting production data to exposing secrets. Built by HOL, it’s free, open source, and already has 400K+ downloads.
MonoCloud is one identity layer for your customers, your APIs, and your agents. Most tools stop at a login box. We go past login into authorization and accountability: decide exactly what every user, service, and AI agent can access, prove what it did, and revoke it in an instant. Fine-grained Cedar authorization, passkeys and SSO, API protection, M2M, and mTLS with certificate-bound trust, all on one platform. Startups get the full platform free for one year.
Kastra is the runtime authorization layer for AI agents. It decides what agents can and cannot do before actions execute, enforcing policies with sub-1 ms latency across tools, prompts, inputs, and outputs. Use one control plane to govern agents and policies across Claude Code, Cursor, Codex, OpenClaw, the Anthropic SDK, the OpenAI SDK, and more. Prevent unauthorized tool use, prompt injection, and exposure of sensitive data before they become incidents. Trust the rules, not the agents.
You've used ChatGPT and Claude for real work. They just do the task. No record of what they touched, no approval on the risky step, nothing you could hand your security team. Great UX, zero governance. Enterprise tools flip it: total control, an interface nobody wants to open. Lunen is what automated AI should be, the clean UX and the full transparency, not one or the other. Now in early access.
The official Tailscale client keeps one tailnet active at a time. TailMux makes work and personal tailnets reachable simultaneously on macOS and Linux, without switching accounts, running multiple system daemons, or using a VM. It runs an isolated embedded node per profile and routes by hostname, with strict no-fallback isolation. Use SSH, RDP/SMB, browsers, curl, git, and npm across tailnets at the same time.
Every challenge is a live and open-source AI agent guarding a secret - with its system prompt published for you to read. Talk it past its own defenses. Land the most approved breaks in a week and win $100K+ in rewards. Free to play, no account needed. New challenge every Monday.
Point your AI agent at Gate. Inherit prompt-injection defense, secret scanning, and a verifiable audit trail. Save tokens automatically. No code changes. Gate ranks #1 across 16 public prompt-injection benchmarks (97.4% F1). Every decision is sealed to an immutable, verifiable blockchain audit trail. Compression saves 20%+ on tokens automatically. No code changes needed. Free tier, no card required.
Autonomous access control security for Vibe-coded apps. Our platform finds and fixes live vulnerabilities in your vibe-apps built on Replit, Lovable, Claude Code, Cursor, and other AI-coding tools. 1-prompt makes your app production-ready in minutes without requiring security expertise.
AI attacks don’t wait for your next sprint. BestDefense continuously pentests every deploy, proves which vulnerabilities are actually exploitable, and generates fixes so high-compliance SaaS teams can patch real risks before remediation windows close. Unlike static scanners, BestDefense validates exploits through execution, cuts false positives, and helps developers move from finding issues to fixing them faster.
Refuse sits in front of npm, pip, cargo, gem, go + 13 more package managers and refuses known-vulnerable installs before they hit disk — the moment you (or your coding agent) run them. Also, Open-source, self-hostable, one Docker container.
Autonomous AI agents are writing and executing code, but running it on your host server is a massive security risk. Vela (powered by the Aegis runtime) solves this. It’s a policy-driven execution guard that uses Firecracker micro-VMs and HMAC capability tokens to safely run untrusted code. Get structured results, fine-grained filesystem/network restrictions, and a full JSONL audit trail. Open-source, MIT licensed, and built for LangChain/LlamaIndex.
AI agents don't just chat anymore; they execute. SolonGate is the zero-trust security layer that controls exactly what your autonomous AI agents can do. We sit directly between LLMs and your internal systems, APIs, or databases. Every action your AI attempts is filtered through our deterministic Policy Engine and an isolated AI Judge. We block risky, unauthorized, or destructive actions before execution. Complete action governance.
ZenVeil helps developers find, understand, and fix security issues without the complexity of traditional security tools. Scan GitHub repositories, local codebases, and APIs for secrets, supply chain risks, and common security issues. Generate AI-powered explanations, remediation guidance, prioritize findings with AI triage, and create pull requests with fixes. Available through both a web dashboard and CLI.
Keep up with your agents. Spotlight reads your Claude Code and Codex sessions and shows you what your agents actually did, and how to get recursively better every session: what to fix now, what to ship better next time, what's worth sharing. One harness or seven, solo or across your team. Free.
Most Mac security tools need agents, signups, or MDM. fort doesn't. One command checks 15+ security settings: FileVault, SIP, firewall, screen lock, local admin rights, Gatekeeper, SSH, AirDrop and more. Reports a score and fixes most issues automatically. Single binary. No telemetry. MIT licensed. Perfect for developers hardening their own Mac, and for teams preparing for SOC 2 or ISO 27001 without the MDM overhead. brew install djadmin/tap/fort
DotBGE encrypts files on-device with no accounts and no servers. Use the iPhone/iPad app to encrypt, decrypt, preview, and sharebge files; use the bge CLI on macOS/Linux for scripts and terminal workflows; or let Claude Code, ChatGPT, and other shell-running agents handlebge files through the bundled skill. Built on the openbge format with identity-based RSA encryption and password mode.
Astra Autonomous Pentesting makes self-healing software the new standard, a category we’re defining after 8 years and 5,000+ real-world pentests. An army of offensive pentesters and bounty hunter agents that discovers complex chained vulnerabilities, an independent validator layer drives false positives to near-zero, and AI-fix agents deliver remediation as native Cursor, Copilot, and Claude Code prompts. The reactive pentest era is over.